Skip to main content
Ryan_Kang
Visitor III
June 11, 2025
Solved

Feature Request – ACL Enhancements and Interface Range Configuration for Managed FortiSwitch

  • June 11, 2025
  • 3 replies
  • 982 views

Hello,

 

I'm reaching out as I couldn’t find the proper place to submit feature requests on the Fortinet website (such as support or partner portals). Therefore, I'm sharing this feedback here in the community forum in hopes it reaches the appropriate team.

 

One of my customers operates a network with approximately 100 FortiSwitches, all integrated via FortiLink with FortiGate.

 

Managing ACLs on FortiSwitches in this environment has been extremely frustrating.

 

Here’s the issue:
I want to apply ACLs that allow or deny traffic based only on destination service ports, while keeping source and destination IPs as 'any'. This is a very common requirement in real-world environments. However, this configuration is not possible when the FortiSwitches are managed by FortiGate via FortiLink.

 

The managed FortiSwitch ACL configuration lacks the ability to define service ports. There is also no option to disable FortiGate control over ACLs, which means that even if I manually configure ACLs directly on each FortiSwitch, those configurations are erased after a certain period—presumably because FortiGate has no corresponding configuration and overwrites them.

 

This is understandable, but still unacceptable in operational environments.

 

Please consider adding the ability to configure ACLs based on service ports directly from FortiGate for managed FortiSwitches.

 

Furthermore, FortiSwitches, unlike other vendors, do not support interface range configuration in CLI, which makes batch operations incredibly time-consuming and error-prone.

 

If you’ve ever tried to configure ACLs on FortiSwitch via FortiGate, you’d know how painful the process is:
You must create the ACL, group it, and then go into each switch to apply it to individual ports one by one. This is an inefficient and unrealistic approach, especially in large-scale deployments.

 

Please improve these features that are most commonly used in real-world operations.
Not being able to configure ACLs based on service ports in managed FortiSwitch mode is deeply disappointing.

 

It would be ideal if there were a setting that allows engineers to choose whether FortiGate should manage ACLs on FortiSwitch or not.

 

In many cases, managing ACLs directly on the FortiSwitch is more practical and preferred, and I believe many other network engineers would agree.

 

Thank you for your consideration.

Best answer by Stephen_G

Hi Ryan,

 

Yes, contact a local sales engineer in your country via email if you can. I'm afraid I can't find the online sections you mean either.

 

I hope that helps!

3 replies

Stephen_G
Staff & Editor
Staff & Editor
June 13, 2025

Hi Ryan_Kang,

 

Thanks for reaching out!

 

For new feature requests, contact your Fortinet Account Manager. They will make contact with the right team to evaluate the feature. From there, we'll evaluate the feature and its potential benefit.

 

I hope that helps!

Stephen_G - Fortinet Community Team
Ryan_Kang
Ryan_KangAuthor
Visitor III
June 14, 2025

Hello Stephen_G,

 

I would like to ask how I can get in touch with a Fortinet Account Manager.

Should I contact a Fortinet engineer or sales representative in my country via email?

 

I recall that there used to be a section on the support website for product or feature inquiries, but I can no longer find it.

 

Do I need to reach out to Fortinet directly via phone or by emailing the appropriate contact person?

 

Thank you in advance for your guidance.

 

Best regards,
Ryan Kang

Stephen_G
Staff & Editor
Stephen_GAnswer
Staff & Editor
June 16, 2025

Hi Ryan,

 

Yes, contact a local sales engineer in your country via email if you can. I'm afraid I can't find the online sections you mean either.

 

I hope that helps!

Stephen_G - Fortinet Community Team
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.